Privacy Policy
Last updated: August 30, 2026
Who We Are
Talk with Benjamin is a cognitive behavioural therapy practice based in Surbiton, Greater London, England. We are committed to protecting your privacy and handling your personal data in accordance with UK data protection laws.
Data Controller: Benjamin Mitchell
Contact Email: benjamin@talkwithbenjamin.uk
Business Address: Surbiton, Greater London, UK
ICO Registration Number: ZB762231
What Information We Collect
When you use our website and services, we collect:
Account Information:
- Email address (required for account creation and Magic Link authentication)
- Name (optional, for personalisation)
Automatically Collected Information:
- IP address (for security and agreement signing audit trail)
- Basic browser information (via server logs)
- Login and access timestamps
Security and Authentication Logs:
- Any email address entered into the Magic Link login form is logged by us, together with IP address, browser information, and timestamp, for security monitoring and fraud prevention
- This applies even if the email address does not belong to an existing account or a link is never clicked
- These logs are accessible only to authorised administrators of the practice
- Separately, our email service provider, Resend, keeps its own delivery logs (e.g. recipient address, delivery status, timestamps) for every Magic Link email sent, under its own retention terms — see “How We Share Your Information” below
Digital Agreement Data:
- Signature data (drawn or typed signatures)
- Agreement signing timestamp and IP address
- Signed PDF documents (stored securely)
Payment Information:
- If you agree to pay for sessions by card, we direct you to a secure Stripe payment link to save your card details
- We do not collect or store your card number ourselves — it is held by Stripe and used to take payment automatically before each session, as set out in your signed agreement
- We retain a record that a card was saved and basic transaction metadata (e.g. amount, date) for accounting purposes
Website Analytics:
- We use Cloudflare Web Analytics, a privacy-friendly, cookieless analytics service, to understand aggregate visitor numbers, device type, country, and referrer for this website
- This does not use cookies or collect personally identifiable information, and does not track you across other websites
Clinical Records:
If you are a therapy client, we also hold clinical records in our separate practice management system, used to deliver and account for your sessions:
- Session administrative data: dates, duration, mode (video, phone, or in-person), and session number
- Session note content: presenting content, intervention, response/outcome, and aftercare plan, together with any risk flags or notes. This is special category (health) data under UK GDPR and is handled with additional safeguards, as set out under “Legal Basis for Processing” below
- Supervision records: discussion notes and safeguarding flags relating to clinical work, kept separately from billing or account data
- Client identifiers used in the clinical system are opaque codes rather than names, and this system is stored separately from your website account
How We Collect Your Information
We collect your personal data when you:
- Create an account on our website
- Request a Magic Link for secure login
- Sign digital therapy agreements
- Contact us via email
- Use our website (through basic server logging)
Legal Basis for Processing
We process your personal data under the following legal bases:
- Legitimate Interest: To provide secure authentication, maintain service security, and deliver therapy services
- Contract: To fulfil our therapy services agreement with you
- Legal Obligation: To comply with accounting, tax, and professional record-keeping requirements
- Consent: For any marketing communications (where you’ve given explicit consent)
- Health or Social Care Purposes: Special category clinical data (session notes, risk flags, and supervision records relating to your therapy) is processed under the health/social care purposes condition (UK GDPR Article 9(2)(h) and Data Protection Act 2018, Schedule 1, Part 1, paragraph 2), which permits processing of health data by a practitioner for the purposes of therapy provision
How We Use Your Information
We use your personal data to:
- Provide Secure Access: Deliver Magic Link authentication for passwordless login
- Service Delivery: Manage your client portal access and digital agreement signing
- Legal Compliance: Maintain audit trails for signed agreements and meet regulatory obligations
- Communication: Send authentication emails and service-related updates
- Security: Monitor and prevent unauthorized access attempts
Magic Link Authentication
We use Magic Link technology for secure, passwordless login:
- Unique, time-limited links sent to the email address entered
- Links expire after 30 minutes for security
- One-time use only - links become invalid after first use
- Every login attempt is logged for security monitoring, including the email address entered, IP address, browser information, and timestamp, whether or not that email belongs to an existing account
- Sessions last 7 days with secure HTTP-only cookies
How We Share Your Information
We share your personal data only with trusted service providers:
Email Service Provider: Resend (for Magic Link delivery and service communications)
Cloud Storage: Cloudflare R2 (for secure PDF document storage)
Database: Cloudflare D1 (for account and session management)
Hosting: Cloudflare Workers (for website delivery)
Payments: Stripe (for secure card storage and per-session billing)
Analytics: Cloudflare Web Analytics (for aggregate, cookieless visitor statistics)
Our clinical practice management system is a separate application from this website and portal, with its own processors:
Clinical Hosting, Database, and Authentication: Cloudflare Workers, Cloudflare D1, and Cloudflare Access (Zero Trust, using Google OAuth) provide hosting, database storage, and staff authentication for the clinical system. This is a separate Cloudflare deployment and a separate authentication mechanism from the Magic Link login used on this website and client portal.
Dashboard Mirror: Google Workspace (Sheets and Drive, via Google Apps Script) is used to maintain a dashboard mirror of session administrative metadata — session dates and completion flags only. Clinical note content, risk flags, and supervision records are never included in this mirror.
Clinical Billing: A separate, independent Stripe integration is used for automated per-session billing for one specific work setting. This is distinct from the Stripe payment-link flow described above under “Payments,” which relates to this website’s client agreements.
All service providers are bound by strict data protection agreements and process data only as instructed.
Resend processes email data (including the recipient address of every Magic Link email) in the United States and keeps its own delivery logs, independent of and in addition to the logs we keep ourselves. Resend deletes this data within 90 days of our account with them ending. For certain limited data — such as records Resend keeps for its own fraud prevention and security purposes — Resend acts as an independent controller in its own right, rather than solely on our instructions. See Resend’s privacy policy at resend.com/legal/privacy-policy for details of their practices.
If you choose to pay by card, Stripe processes and stores your card details directly — we never see or store your full card number. Stripe acts as an independent controller for the payment data it holds, in accordance with its own privacy policy at stripe.com/privacy. We only retain confirmation that a card was saved and basic transaction records for accounting purposes.
Cloudflare Web Analytics collects aggregate, anonymised visit statistics (e.g. page, device type, country, referrer) for this website. It does not use cookies and does not collect information that identifies you personally.
We never sell your personal data to third parties.
Data Storage and Security
Storage Locations:
- Account data: Cloudflare D1 database (EU/UK regions)
- Signed PDFs: Cloudflare R2 storage (encrypted at rest)
- Email delivery: Resend (processed in the United States)
- Clinical records: Cloudflare D1 (a separate database and deployment from the website), encrypted at rest by the platform
Security Measures:
- Encryption of data in transit and at rest
- Secure session management with HTTP-only cookies
- Rate limiting on authentication attempts
- Regular security monitoring and updates
- Limited access on a need-to-know basis
Data Retention
We retain your personal data for:
- Account Information: Until you delete your account, then 30 days for cleanup
- Session Data: 7 days (automatic expiry)
- Magic Links: 30 minutes (automatic expiry)
- Signed Agreements: 7 years after your last therapy session (professional standards requirement) — this covers the signed agreement PDF and its audit trail specifically
- Clinical Session Records: Session notes, risk flags, and supervision content relating to your therapy are retained separately for 7 years from your last treatment date, driven by our professional indemnity insurance requirements (Balens) and NCPS professional guidance. In practice this period runs concurrently with, and covers the same span as, the Signed Agreements retention above, but the two are tracked separately because they cover different records. In limited circumstances — such as an active complaint or legal matter — clinical record retention may be extended beyond 7 years
- Security and Authentication Logs: Retained only as long as necessary for security monitoring and fraud prevention purposes. We do not currently apply an automatic deletion schedule to these logs. You may request erasure of your own entries at any time (see Your Rights, below)
Your Rights
Under UK data protection law, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Rectification: Ask us to correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Restrict Processing: Ask us to limit how we use your data
- Data Portability: Request your data in a portable format
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent for any consent-based processing
Erasure requests relating to clinical records (session notes, risk flags, and supervision content) are subject to the 7-year professional retention requirement described under “Data Retention” above. Where a request falls within that retention window, we may decline to erase the record under the relevant statutory exemption, while still fulfilling any part of your request that isn’t subject to that requirement.
To exercise these rights, contact us at benjamin@talkwithbenjamin.uk. We’ll respond within one month.
International Transfers
We use UK and EU-based service providers where possible. Some data is transferred outside the UK:
- Cloudflare: UK/EU data centres with appropriate safeguards
- Resend: processes email data in the United States. This transfer is protected by UK Standard Contractual Clauses incorporated into our agreement with Resend, and Resend’s certification under the UK Extension to the EU-U.S. Data Privacy Framework
Any data transfers outside the UK/EU are protected by adequacy decisions or standard contractual clauses.
Children’s Privacy
Our services are intended for adults aged 18 and over. We do not knowingly collect personal data from individuals under 18 without appropriate consent.
Changes to This Policy
We may update this privacy policy to reflect changes in our practices or legal requirements. We’ll notify you of significant changes via email or website notice. The “last updated” date shows when changes were made.
Contact Us
If you have questions about this privacy policy or our data practices:
Email: benjamin@talkwithbenjamin.uk
Response Time: Within 2 business days
Complaints
If you’re not satisfied with how we handle your personal data, you can complain to the Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF